Intego: Adobe CS4 crack app has variant of iServices trojan
The folks over at Intego let the world know about a new trojan making the rounds along with copies of an application designed to crack Adobe Creative Suite 4. They consider the risk "serious."
If you don't download software using peer-to-peer tools like BitTorrent, then you're perfectly safe. You can stop reading this story, if you like. If you're one of the 5,000 people who recently downloaded and installed the serial crack, then you have a bad day ahead of you.
The malware, after asking for your administrator password, installs an executable with a random name in /var/tmp, a folder that isn't deleted when the computer restarts.
The randomly-named program will install itself in /usr/bin/DivX, create a startup item in /System/Library/StartupItems/DivX, and if it has root privileges, save a hash of your password in the file /var/root/.DivX.
The software then listens on a random TCP port and awaits instructions from its evil overlords. With an infected computer's root password, those in control of the software will be able to execute commands on the infected computer, including deleting files and performing malicious network tasks.
Late last week, pirated copies of iWork '09 were infected with similar malware.
Intego VirusBarrier X4 and X5, as you might imagine, protect you against the Trojan. Either looking for (and removing) the files mentioned above or using a virus removal utility is recommended.
Also recommended: Not downloading pirated software (and their associated tools) on peer-to-peer networks. If you do choose to get your software that way, you have nobody to blame but yourself if your system gets infected.
Share
Categories
The folks over at Intego let the world know about a new trojan making the rounds along with copies of an application designed to crack...
Add a Comment
I find it hilarious that the few of you that admit to pirating the software say you "purchased" it after.
Sure.
Just remember that bittorrent isnt illegal, and its probably quite legal to distribute copies of iWork 09 on it, as long as its the same trial version that available on the apple website, its just a case of distributing it not on apples website, as long as you're not chucking in a serial or trojan, whats the problem of someone getting it from bittorrent or the direct download from apple.
bittorrent isnt the problem, its the mindless morons who put illegal stuff on it.
I was wondering when this would start happening. The very first time I downloaded major software using bit torrent, I wondered why bigger software companies didn't start releasing trashed versions of their software on p2p sites. I don't like it, but I think it's the best strategy for them (not that that's what's happening here) to just make people stay away from illegal copies. I downloaded the CS3 crack last year, and it was just fine. I just needed more time to evaluate it than the trial period allowed. A couple months later I purchased a license. When I did I felt so much better because I never trusted the cracked version.
I'm not bashing bit torrent or p2p. I think they're legit. But I'm not installing cracked anything anymore.
Does anyone else think that Intego should stop advertising that they pirate software? Most software pirates are intelligent in that they don't go out and warn others they found something bad in something they got illegally.
January 27 2009 at 4:01 AM Report abuse Permalink rate up rate down Replyinteresting- and to alex baites, windows ad Linux and leopard are all over. you just have to know where and who to get it from, see and if you crack stuff yourself , there is no pain but only gain. and you can even get portable versions of windows and then save it to your hard drive, even if your had drive is corrupt, you can still boot somewhat, just not access files, but you get to a boot from disc and help screen.
but really, just get a flash drive and copy a PORTABLE version of windows and plug it in to either a Linux or mac etc. and save and run, with some tweeking you can have it show up on boot screen to boot into either windows or default OS
but people who get cracked versions should either be smart enough to know to check for viruses or corruptions
and for people who have or pottentialy may have the virus, watch out for sending emails and IMing, a virus can easily just copy itself and send itself to your whole email list If you open it.
for people unsure if they have it, you can either search for it. or check for high CPU , if it is jumping whn you clearly have nothing open or it's slowing down your computer, you can count on someone in you backdoor of your computer, then I would suggest disconnecting from Internet and deleting ad uninstalling the corrupt file (iWork etc.) and bringing to a computer "geek" and fell him what happened. worst case scenario wipe hat drive reinstall mac etc from your disk. or if that doesn't work and they tried to bomb you with the computer, call 911 and get a bomb squad and tell apple.
yea I'm serious they can explode your computer, physically scratch your hard drive . and well make stuff catch fire.
hope this helps for everyone!
Listen to all of the millioaires. Do you ever think that maybe the people downloading these things either can't afford a $800 program or are underaged?
Get off your elitest high horses. I guarantee the vast majority of you have downloaded quite a few illegal items in the past. Even if you don't have the balls to admitt it.
Gosh, about everything nowadays you can get from a torrent except for an operating system. I haven't heard of Leopard being availiable to download in a torrent. What kind of protection does it have? Why can't Apple use the same type of protection with iWork and iLife?
January 26 2009 at 5:26 PM Report abuse Permalink rate up rate down ReplyLeopard (rightly) has no protection and it's all over the place.
January 26 2009 at 5:31 PM Report abuse Permalink rate up rate down ReplyI'd like to point out the epic stupidity of anyone who gets these - in both iWork 09 and CS4, you could activate the software without a keygen at all, or without even downloading it from an illegal source. Just download a trial, _____________________ (I'm obviously not going to tell people how to steal the software), and poof, it's registered and you payed zero.
I did that very thing with cs4 for a week after the trial expired and while I waited for my retail copy to ship (adobe takes so long to ship stuff). Yea, I pirated it for a week, but now I have legit copies of both and no Trojans.
I'm just saying, if you pirate, pirate smartly. Then buy it.
"The fact is that a lot of people who COULD afford software choose to pirate it because it's free..." --Drakhul
True enough. But it is also true that people who do buy software (and try to keep it reasonably up-to-date) get totally reemed by software developers over the years. Sure there's usually an upgrade price for owners of previous versions, but if you add the cost of all the upgrades to the original product cost, you're paying many hundreds (or even thousands) of dollars over the years for run-of-the-mill programs that should really include free or very low cost updates for the life of the product. The way things are, the total cost of ownership for fairly simple programs (Toast and StuffIt are two examples that come to mind) becomes astronomical before you know it.
I agree 100%, but that does not negate the fact that if you use copyrighted software and don't pay for it, you are stealing.
Back in the dark ages when I used a PC, I used to pirate everything... even the OS! Now I am grown and I know better.
i checked in all the locations listed in the article about where the malicious files would be created and they aren't there (i viewed all hidden files too using a terminal command).
So does that mean my mac isn't infected?
Probably, but just wait until morphing Trojans are released for the real fun.
January 26 2009 at 4:22 PM Report abuse Permalink rate up rate down ReplyHot Apps on TUAW
Deals of the Day
more deals- Refurb Apple MacBook Air Laptops: 12" 64GB SSD for $699 + free shipping
- JVC Motion Sensing Clock Radio with Dual iPod Docks for $55 + free shipping
- Apple iPhone Headset with Mic for $4 + $2 s&h
- miFrame Picture Frame Dock for iPad for $64 + $8 s&h
- Refurb Apple iPod nano 8GB MP3 Player for $99 + free shipping, 16GB for $119
- Hannspree Apple-Shaped 28" 1080p LCD HDTV for $270 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



40 Comments